CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
4,085 results Clear all
CVE-2014-1295 EPSS 0.00
Apple Iphone OS < 7.1 - Authentication Bypass
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
CWE-287 Apr 23, 2014
CVE-2012-5032 EPSS 0.01
Cisco IOS <15.1(1)SY3 - DoS
The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.
CWE-287 Apr 23, 2014
CVE-2012-4658 EPSS 0.00
Cisco IOS <15.1(1)SY3 - DoS
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.
CWE-287 Apr 23, 2014
CVE-2014-2341 1 PoC Analysis EPSS 0.05
CubeCart <5.2.9 - Info Disclosure
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
CWE-287 Apr 22, 2014
CVE-2014-2665 EPSS 0.00
MediaWiki <1.19.14, 1.20.x<1.21.8, 1.22.x<1.22.5 - Info Disclosure
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.
CWE-287 Apr 20, 2014
CVE-2014-1517 EPSS 0.00
Mozilla Bugzilla - Authentication Bypass
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.
CWE-287 Apr 20, 2014
CVE-2014-1984 EPSS 0.01
Cybozu Remote Service Manager <3.1.1 - Session Fixation
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Apr 19, 2014
CVE-2014-2338 EPSS 0.00
strongSwan <5.1.3 - Auth Bypass
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
CWE-287 Apr 16, 2014
CVE-2014-2828 EPSS 0.01
Openstack Keystone < 8.0.0a0 - Authentication Bypass
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
CWE-287 Apr 15, 2014
CVE-2014-0138 EPSS 0.01
cURL/libcurl <7.36.0 - Open Redirect
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
CWE-287 Apr 15, 2014
CVE-2014-0357 EPSS 0.02
Amtelco miSecureMessages - Info Disclosure
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.
CWE-287 Apr 15, 2014
CVE-2014-0353 EPSS 0.00
ZyXEL Wireless N300 NetUSB NBG-419N <1.00(BFQ.6)C0 - Auth Bypass
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.
CWE-287 Apr 15, 2014
CVE-2014-0348 EPSS 0.00
Artiva Workstation <1.3.9 - Auth Bypass
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a Windows client machine.
CWE-287 Apr 15, 2014
CVE-2013-7366 EPSS 0.01
SAP SDM - DoS
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
CWE-287 Apr 10, 2014
CVE-2014-2128 EPSS 0.00
Cisco ASA <9.1.3.2 - Auth Bypass
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.
CWE-287 Apr 10, 2014
CVE-2014-0166 1 PoC Analysis EPSS 0.32
WordPress <3.7.2, <3.8.2 - Info Disclosure
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.
CWE-287 Apr 10, 2014
CVE-2014-0635 EPSS 0.00
EMC Vplex Geosynchrony - Authentication Bypass
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Apr 01, 2014
CVE-2014-1982 1 PoC Analysis EPSS 0.10
Alliedtelesis Img646bd Firmware - Authentication Bypass
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.
CWE-78 Mar 31, 2014
CVE-2014-0132 EPSS 0.01
389 Directory Server <1.2.11.26 - Privilege Escalation
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
CWE-287 Mar 18, 2014
CVE-2014-2047 EPSS 0.00
ownCloud <6.0.2 - Info Disclosure
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
CWE-287 Mar 14, 2014